Re: DH parameters from http://www.ietf.org/internet-drafts/draft-iet f-ipsec-ike-modp-groups-04.txt return DH_NOT_SUITABLE_GENERATOR

2002-04-28 Thread Nils Larsch
Hi Ben, [...] Note that RFC 2412 says: Note that 2 is technically not a generator in the number theory sense, because it omits half of the possible residues mod P. From a cryptographic viewpoint, this is a virtue., which is precisely the type of generator I use for Lucre. To check for that,

Re: DH parameters from http://www.ietf.org/internet-drafts/draft-iet f-ipsec-ike-modp-groups-04.txt return DH_NOT_SUITABLE_GENERATOR

2002-04-27 Thread Nils Larsch
On Thursday, 25. April 2002 22:47, you wrote: Hi, I'm tring to use DH params from http://www.ietf.org/internet-drafts/draft-ietf-ipsec-ike-modp-groups-04.txt http://www.ietf.org/internet-drafts/draft-ietf-ipsec-ike-modp-groups-04.tx t , but none get imported in openssl, and openssl

Re: DH parameters from http://www.ietf.org/internet-drafts/draft-iet f-ipsec-ike-modp-groups-04.txt return DH_NOT_SUITABLE_GENERATOR

2002-04-27 Thread Ben Laurie
Nils Larsch wrote: On Thursday, 25. April 2002 22:47, you wrote: Hi, I'm tring to use DH params from http://www.ietf.org/internet-drafts/draft-ietf-ipsec-ike-modp-groups-04.txt http://www.ietf.org/internet-drafts/draft-ietf-ipsec-ike-modp-groups-04.tx t , but none get imported